2017-02-07 16:05:53 +00:00
< md-content flex layout = "column" ng-if = "submenuNavItem == 'fim'" ng-controller = "overviewFimController" >
2017-02-13 19:58:44 +00:00
<!-- Kibana search bar -->
< kbn-searchbar ng-if = "tabView == 'panels'" > < / kbn-searchbar >
2017-02-10 21:33:49 +00:00
<!-- No results message -->
2017-02-13 20:46:16 +00:00
< md-content flex layout = "row" layout-align = "start start" ng-if = "!results && tabView == 'panels'" >
2017-02-10 21:33:49 +00:00
< md-card flex layout = "column" >
< md-card-content style = "text-align: center;" >
2017-02-13 20:46:16 +00:00
No results for selected time interval
2017-02-10 21:33:49 +00:00
< / md-card-content >
< / md-card >
< / md-content >
2017-02-07 16:05:53 +00:00
<!-- View: Discover -->
< md-content style = "background-color: white" flex layout = "column" layout-align = "start space-around" ng-if = "tabView == 'discover'" >
< kbn-disfull table-height = "1000px;" dis-a = "(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
2017-02-14 18:33:24 +00:00
dis-filter="rule.groups:syscheck AND manager.name: {{defaultManager ? defaultManager : '*'}}"
2017-02-07 16:05:53 +00:00
infinite-scroll="true">
< / kbn-disfull >
< / md-content >
<!-- View: Panels -->
2017-02-10 21:33:49 +00:00
< div ng-if = "tabView == 'panels' && results" >
2017-02-07 16:05:53 +00:00
< md-content layout = "row" >
2017-07-10 19:18:51 +00:00
< div flex = "10" layout = "column" class = "no-legend" >
2017-02-07 16:05:53 +00:00
< md-card >
< md-card-content >
< kbn-vis vis-height = "72px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:Added),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter = 'rule.id: 554' >
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card >
< md-card-content >
< kbn-vis vis-height = "72px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20full_log:%22Integrity%20checksum%20changed%22%20NOT%20location:%20syscheck-registry')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'Modified'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter = '(rule.id: 550 OR rule.id: 551 OR rule.id: 552 OR rule.id: 555)' >
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card >
< md-card-content >
< kbn-vis vis-height = "72px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20full_log:%22was%20deleted%22%20NOT%20location:%20syscheck-registry')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:Deleted),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter = 'rule.id: 553' >
< / kbn-vis >
< / md-card-content >
< / md-card >
< / div >
< div flex layout = "column" >
< md-card >
< md-card-content >
< span class = "md-headline" > Events over time< / span >
< kbn-vis vis-height = "280px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22')),uiState:(vis:(legendOpen:!t)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:auto,min_doc_count:1),schema:segment,type:date_histogram),(enabled:!t,id:'2',params:(field:rule.description,order:desc,orderBy:'1',size:8),schema:group,type:terms)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,interpolate:step-after,legendPosition:right,mode:stacked,orderBucketsBySum:!t,scale:linear,setYExtents:!f,shareYAxis:!t,smoothLines:!t,times:!(),yAxis:()),title:'FIM%20Alerts%20over%20time',type:area))"
vis-filter='rule.groups:"syscheck"'>
< / md-card-content >
< / md-card >
< / div >
< div flex = "20" layout = "column" >
< md-card >
< md-card-content >
< span class = "md-headline" > Top user owners< / span >
2017-03-06 17:50:45 +00:00
< kbn-vis vis-height = "100px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!t)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:syscheck.uname_after,order:desc,orderBy:'1',size:3),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users',type:pie))"
2017-02-07 16:05:53 +00:00
vis-filter='rule.groups:"syscheck"'>
< / md-card-content >
< / md-card >
< md-card >
< md-card-content >
< span class = "md-headline" > Top group owners< / span >
2017-03-06 17:50:45 +00:00
< kbn-vis vis-height = "100px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!t)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:syscheck.gname_after,order:desc,orderBy:'1',size:3),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users',type:pie))" vis-filter = 'rule.groups:"syscheck"' >
2017-02-07 16:05:53 +00:00
< / md-card-content >
< / md-card >
< / div >
< / md-content >
< md-content layout = "row" >
< md-card flex layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
vis-filter="syscheck.event: modified AND location: syscheck">
< / kbn-vis-value >
< div class = "ng-binding" > Last file modified< / div >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-17 20:38:31 +00:00
< / md-card >
2017-02-07 16:05:53 +00:00
< md-card flex layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
vis-filter="syscheck.event: added AND location: syscheck">
< / kbn-vis-value >
< div class = "ng-binding" > Last file added< / div >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-17 20:38:31 +00:00
< / md-card >
2017-02-07 16:05:53 +00:00
< md-card flex layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
vis-filter="syscheck.event: deleted AND location: syscheck">
< / kbn-vis-value >
< div class = "ng-binding" > Last file deleted< / div >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-17 20:38:31 +00:00
< / md-card >
2016-09-18 17:20:21 +00:00
2017-02-07 16:05:53 +00:00
< / md-content >
2016-09-20 08:55:43 +00:00
2017-02-07 16:05:53 +00:00
< md-content layout = "row" >
< md-card flex = "33" >
2017-02-16 12:51:11 +00:00
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Top file changes< / span >
< / md-card-title-text >
< / md-card-title >
2016-09-20 08:55:43 +00:00
< md-card-content >
2017-03-06 11:47:44 +00:00
< kbn-vis vis-height = "193px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Changed',type:pie))"
2017-07-10 21:26:40 +00:00
vis-filter='rule.groups:"syscheck" AND full_log:"Integrity checksum changed" NOT location: syscheck-registry'>< / kbn-vis >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-18 17:20:21 +00:00
< / md-card >
2017-02-07 16:05:53 +00:00
< md-card flex = "33" >
2017-02-16 12:51:11 +00:00
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Root user file changes< / span >
< / md-card-title-text >
< / md-card-title >
2016-09-20 08:55:43 +00:00
< md-card-content >
2017-03-06 11:47:44 +00:00
< kbn-vis vis-height = "193px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Changed',type:pie))"
2017-07-10 21:26:40 +00:00
vis-filter='rule.groups:"syscheck" AND full_log:"Integrity checksum changed" NOT location: syscheck-registry AND root'>< / kbn-vis >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-18 17:20:21 +00:00
< / md-card >
2017-02-07 16:05:53 +00:00
< md-card flex = "33" >
2017-02-16 12:51:11 +00:00
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > World writable modified files< / span >
< / md-card-title-text >
< / md-card-title >
2016-09-20 08:55:43 +00:00
< md-card-content >
2017-03-06 11:47:44 +00:00
< kbn-vis vis-height = "193px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20_exists_:syscheck.perm_after%20AND%20%20(syscheck.perm_after:%2F%5B0-7%5D%7B5%7D(%5B2367%5D).*%2F)')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Files',type:pie))"
2017-07-10 21:26:40 +00:00
vis-filter='rule.groups:"syscheck" AND _exists_:syscheck.perm_after AND (syscheck.perm_after:/[0-7]{5}([2367]).*/) '>< / kbn-vis >
2016-09-20 08:55:43 +00:00
< / md-card-content >
2016-09-18 17:20:21 +00:00
< / md-card >
2017-02-07 16:05:53 +00:00
2016-09-18 17:20:21 +00:00
2017-02-07 16:05:53 +00:00
< / md-content >
2016-09-20 08:55:43 +00:00
2017-03-02 20:28:38 +00:00
< md-content layout = "row" flex = "100" >
2017-02-07 16:05:53 +00:00
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:agent.name,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "location: syscheck" > < / kbn-vis-value >
< div class = "ng-binding" > Top agent< / div >
< / md-card-content >
< / md-card >
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.pci_dss,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "location: syscheck" > < / kbn-vis-value >
< div class = "ng-binding" > Top PCI Requirement< / div >
< / md-card-content >
< / md-card >
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.perm_after,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "location: syscheck" > < / kbn-vis-value >
< div class = "ng-binding" > Most common permissions< / div >
< / md-card-content >
< / md-card >
< md-card flex = "40" layout = "column" >
< md-card-content style = "text-align: center;" >
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "location: syscheck" > < / kbn-vis-value >
< div class = "ng-binding" > Most modified file< / div >
< / md-card-content >
< / md-card >
2016-09-20 08:55:43 +00:00
2017-02-07 16:05:53 +00:00
< / md-content >
< md-content flex layout = "row" >
< md-card flex >
2017-01-30 15:55:55 +00:00
< md-card-title >
2017-02-07 16:05:53 +00:00
< md-card-title-text >
< span class = "md-headline" > Events summary< / span >
< / md-card-title-text >
2017-01-30 15:55:55 +00:00
< / md-card-title >
2017-02-07 16:05:53 +00:00
< md-card-content >
< kbn-vis vis-height = "450px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:Agent,field:agent.name,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:File,field:syscheck.path,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:Event,field:syscheck.event,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Description,field:rule.description,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
vis-filter="rule.groups: syscheck">
< / kbn-vis >
< / md-card-content >
< / md-card >
2016-09-17 20:38:31 +00:00
2017-02-07 16:05:53 +00:00
< / md-content >
< / div >
2016-09-20 14:20:29 +00:00
< / md-content >